VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 14 of 506
  • CVE-2019-9002CriFeb 22, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

  • CVE-2018-18996CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.02

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.

  • CVE-2019-5886CriJan 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system…

  • CVE-2018-16591CriSep 10, 2018
    risk 0.64cvss 9.8epss 0.02

    FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.

  • CVE-2018-11541CriJul 9, 2018
    risk 0.64cvss 9.8epss 0.02

    A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446, 6.1.x up to Build 492, and 7.0.x up to…

  • CVE-2018-8755CriJun 25, 2018
    risk 0.64cvss 9.8epss 0.01

    NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downloading this file, an attacker can access the admin password, WPA key, and any config information of the device.

  • CVE-2018-10251CriMay 4, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitrary code and gain full…

  • CVE-2018-0015CriFeb 22, 2018
    risk 0.64cvss 9.8epss 0.01

    A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Agent is executing. If…

  • CVE-2018-5377CriJan 12, 2018
    risk 0.64cvss 9.8epss 0.02

    Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.

  • CVE-2017-12582CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.01

    Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.

  • CVE-2017-9232CriMay 28, 2017
    risk 0.64cvss 9.8epss 0.48

    Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

  • CVE-2025-20125CriFeb 5, 2025
    risk 0.63cvss 9.1epss 0.16

    A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and…

  • CVE-2024-31997CriApr 10, 2024
    risk 0.63cvss 9.9epss 0.74

    XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user's own profile can create…

  • CVE-2021-4374CriJun 7, 2023
    risk 0.63cvss 9.1epss 0.16

    The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2021-30713HigKEVSep 8, 2021
    risk 0.63cvss 7.8epss 0.07

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2018-7702CriMar 15, 2018
    risk 0.63cvss 9.1epss 0.14

    SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.

  • CVE-2026-66887CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    The affected products are missing authorization on state-changing CGIs and session checks are not performed.

  • CVE-2026-78069CriSep 3, 2026
    risk 0.62cvss —epss 0.00

    Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check anywhere in the code. It…

  • CVE-2026-11807CriJun 23, 2026
    risk 0.62cvss 9.6epss 0.01

    A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary…

  • CVE-2026-48582CriJun 19, 2026
    risk 0.62cvss 9.6epss 0.01

    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.